![]() |
For example:
Code:
<if condition="$bbuserinfo['userid']>0">{param}<else />This code is not visible for Guests</if> Code:
<if condition="$bbuserinfo['reputation']>=100">{param}<else />This code is only visible for reputation points.</if> I found out that it would parse vb variables directly in the post. The question is if there is a security matter / issue or not?! For example I can write in my post Code:
$bbuserinfo[reputation] directly in my post show my reputation value. So I am afraid it could be used by members for malicious actions or is this impossible? |
The conditionals work for me.
It's not really a security risk but you may have data you don't want them to see. |
Could you use this to specify the bbcode to only be used in a particular forum? If so, what code would you use?
|
Hmmm, interesting. I'm going to click install for now and download and install this to my site later!
|
There are a two problems with this mod. One is where a member can type $bbuserinfo[var] and it will output the value in the database but only for their userid. I used preg_replace to fix the problem.
Another is when someone types an array with either single or double quotes $var['foo'] or $var["foo"]. Can anybody help with the second problem? |
Great mod , even with the simple example you wrote it'll be much fun to use it
|
Did you include the fix for the first problem in the plugin yet?
For restricting multiple usergroups, can you use the is_member_of() function instead of the boolean operator? (I know that this works in templates, not sure about here) Example: <if condition="is_member_of($bbuserinfo,{option})">{pa ram}</if> [bbcode_name=5,6]visible to mods and admins only[/bbcode_name] or you might need quotes, depending on how things are parsed, and whether or not this is related to problem #2 above: [bbcode_name='5,6']visible to mods and admins only[/bbcode_name] I am concerned about the security risk, because I have a ton of private/hidden profile fields with personal information about my users that I wouldn't want people to have access to |
Quote:
Installed and working great! But, is there any security/abuse concern here? Can this be exploited? --RayJ |
Quote:
PHP Code:
Thanks for any info! --RayJ PS: PHP Code:
|
It seems as if this only works on new/updates posts. It fails to function for bbcodes in the post-cache. Any info on how to fix this?
Thanx, RayJ |
All times are GMT. The time now is 11:24 AM. |
Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information | |
---|---|
|
|
![]() |
|
Template Usage:
Phrase Groups Available:
|
Included Files:
Hooks Called:
|